Construction & InfrastructureRegulations, Compliance & Governance
GDPR and data governance for AI on construction and infrastructure projects
Project data governance under GDPR is the discipline of knowing which personal data a construction or infrastructure site creates — camera footage, biometric templates, access logs, drone imagery — deciding which company in the chain is the controller for each of them, and settling what happens to all of it when the project reaches handover.

Key takeaways
- A construction site is the hardest personal-data environment in industry because it is a temporary workplace staffed by other companies' people: one camera network watches employees of the main contractor, six subcontractors, two labour agencies and the client's own inspectors, and none of them share an HR system.
- Site CCTV with computer vision — PPE detection, exclusion-zone alerts, plant-proximity warnings — is systematic monitoring of workers, so a DPIA is required before the system is energised, not after the first incident it detects.
- Biometric turnstiles process special category data under Article 9, and the necessity test is unforgiving: the ICO ordered Serco Leisure and associated trusts to stop processing the biometric data of more than 2,000 employees for attendance checking and to destroy it, because cards and fobs were a less intrusive option.
- In a joint venture the joint-controller question under Article 26 is answered whether or not anyone writes it down — and if nobody does, every JV member carries the full controller obligation for everything the shared site systems did.
- The retention question nobody plans for is handover: at practical completion the project stops existing, and four years of footage, access logs and biometric templates need an owner, a deletion date or a documented transfer — decided at contract award, not on the last day.
Abbreviations used on this page
- GDPR
- General Data Protection Regulation (EU) 2016/679, and UK GDPR in Great Britain
- DPIA
- Data protection impact assessment (GDPR Article 35)
- LIA
- Legitimate interests assessment — the three-part test behind Article 6(1)(f)
- RoPA
- Records of processing activities (GDPR Article 30)
- DPO
- Data protection officer
- CDE
- Common data environment — the project's shared information store under ISO 19650
- CDM 2015
- Construction (Design and Management) Regulations 2015
- JV
- Joint venture — two or more contractors delivering one project as a single entity
- PC
- Practical completion — the point at which the works are handed to the client
- CV
- Computer vision — image models such as PPE detection or exclusion-zone alerting
- ANPR
- Automatic number-plate recognition, typically on the site gate
- EDPB
- European Data Protection Board
Free · 8 questions · ~3 minutes
Score your project on the governance ladder
Eight questions, one at a time, about three minutes. Answer them and we build your personalised project report — your stage on the ladder, your score on each of the four dimensions, and the specific gap a client's auditor, a union representative or a regulator would find first — and send it to your inbox. Your result doubles as the scoping input for a site data register and DPIA programme.
0 of 8 answered
Pick an option to continue
Report ready
Your personalised project report is ready
Tell us where to send it. Your stage appears on screen straight away, and the full report — dimension scores, the enforcement patterns closest to your gaps, and the first 90 days of remediation on one live site — arrives in your inbox.
Your result
Your full report is on its way to your inbox.
Stage 1 · Unmapped
The site creates personal data continuously and nobody can name the systems, the purposes or the companies that hold it.
Your next moveWalk one live site and build the register: every capture device, what it sees, who bought it, who can watch it, and how long the footage survives.
Stage 2 · Inventoried
A register exists and the paperwork looks finished, but it describes the company rather than the project — and nothing on site enforces what it claims.
Your next moveTake the highest-risk system on one live project — usually the camera estate with analytics — and make the paperwork true in the equipment: purpose, configuration, retention, access.
Stage 3 · Controlled
Controls are enforced in the site systems themselves: assessments precede energisation, models run on the narrowest useful data, and retention is set where the footage lives.
Your next moveWrite the controller allocation down: an Article 26 arrangement for the shared systems, flow-down terms in the subcontracts, and one project evidence pack that a client auditor can read.
Stage 4 · Evidenced
The project can prove it: a live register, assessments tied to site changes, a written joint-controller arrangement, consultation records and an agreed handover data schedule.
Your next movePush the artefacts upstream and downstream: prequalification questions, standard JV arrangement, subcontract flow-down clauses, and a priced handover data schedule in every contract.
Stage 5 · Trusted
Governance travels with the work: it is asked for at prequalification, flowed down in subcontracts, and closed out at handover as a priced, certified deliverable.
Your next moveWire governance review to project events — site set-up, package award, supplier change, model update, handover — and rehearse the awkward scenarios before they arrive unannounced.
0 / 24
Personal-data inventory
— / 6
Lawful basis & DPIA
— / 6
Controller roles across the chain
— / 6
Retention & handover
— / 6
Your score maps to a stage on the project governance ladder. The dimension breakdown matters more than the total: the lowest dimension is the one a client's auditor, a union representative or a regulator will reach first, and it is where the next fortnight of effort belongs. Your lowest-scoring dimension is —, and that is where the next investment belongs.
Your score maps to a stage on the project governance ladder. The dimension breakdown matters more than the total: the lowest dimension is the one a client's auditor, a union representative or a regulator will reach first, and it is where the next fortnight of effort belongs.Your four dimensions score evenly, so there is no single weak link to attack — follow the stage’s next move above rather than picking a dimension.
Want the weakest dimension turned into a site plan?
We will walk your project, privacy and commercial leads through the dimension scores, test them against the site systems actually running, and leave you with a costed 90-day plan for the weakest dimension on one live project. No obligation, and you keep the plan either way.
How the score maps to a stage
- 0–5 — Stage 1, Unmapped. The site creates personal data continuously and nobody can name the systems, the purposes or the companies that hold it.
- 6–11 — Stage 2, Inventoried. A register exists and the paperwork looks finished, but it describes the company rather than the project — and nothing on site enforces what it claims.
- 12–16 — Stage 3, Controlled. Controls are enforced in the site systems themselves: assessments precede energisation, models run on the narrowest useful data, and retention is set where the footage lives.
- 17–21 — Stage 4, Evidenced. The project can prove it: a live register, assessments tied to site changes, a written joint-controller arrangement, consultation records and an agreed handover data schedule.
- 22–24 — Stage 5, Trusted. Governance travels with the work: it is asked for at prequalification, flowed down in subcontracts, and closed out at handover as a priced, certified deliverable.
What GDPR data governance means on a construction project
Why a temporary site staffed by other companies' people is the hardest personal-data environment in industry — and the path that data actually takes, from the turnstile to the client's asset record.
GDPR data governance on a construction or infrastructure project is the discipline of knowing which personal data the site creates, deciding which company in the chain is the controller for each of those flows, and settling what happens to all of it at handover. The site systems that matter are the ones bought as operational kit rather than as data systems: cameras running computer vision for PPE and exclusion-zone alerting, biometric or card turnstiles, wearables and proximity tags, drone and 360 capture, plant telematics that identifies its operator. Every one of them processes information about identifiable people, so the General Data Protection Regulation (opens in a new tab) applies in full — and on a project it applies to several companies at once.
What makes a site different from a factory or an office is that the workplace is temporary and the workforce belongs to somebody else. A large project gate admits employees of the principal contractor, of six or more subcontractors, of two labour agencies, of the client's own inspection team, plus delivery drivers, statutory undertakers and visitors — populations that share no HR system, no induction database and no employment relationship. The camera that watches the deck watches all of them. The turnstile that records their arrival records them for a supplier's platform. Nobody in that picture has the single, tidy employer–employee relationship that most workplace monitoring guidance assumes, which is why the questions of lawful basis, transparency and controllership are harder here than anywhere else in industry.
The regulation does not prohibit any of this. It asks for an evidence discipline: a lawful basis for each purpose (Article 6 (opens in a new tab)), collection limited to what the purpose needs (Article 5 (opens in a new tab)), a stricter gate where biometric data is used to identify someone (Article 9 (opens in a new tab)), an impact assessment before high-risk processing begins (Article 35 (opens in a new tab)), a written allocation where two or more organisations decide purposes together (Article 26 (opens in a new tab)), transparency to the people in the data, and retention that ends. UK projects carry the same duties under UK GDPR, with the ICO's guidance on monitoring workers (opens in a new tab) as the operative reference. None of these obligations is AI-specific. What AI changes is that a camera which used to record for a security guard now evaluates every person in frame, continuously, and produces a searchable record of what they were doing.
This page reads those obligations through a five-stage project governance ladder — Unmapped, Inventoried, Controlled, Evidenced, Trusted — because the contractors who get into trouble are rarely the ones running monitoring; they are the ones who cannot account for it. The ladder is ordered by dependency: you cannot assign a basis to a system you have not registered, you cannot minimise data whose purpose is unstated, you cannot allocate controllership you have not analysed, and you certainly cannot close out at handover an archive nobody knew existed. The diagram below is the flow the whole page is about.
How personal data moves through a project, from the gate to the asset record
The same estate every large site now runs, drawn with the three moments that decide whether it is lawful: the induction join that turns a face or a tag into a named person, the point where several companies share one system and somebody decides its purposes, and practical completion, when the project stops existing and its archives need an owner.
- Human in the loop
- Data & feeds
- Where value leaks
- AI / model
- System-of-record action
The process, in words
- On site, the data is created by everyone and about everyone: the workforce of several employers, plus visitors and neighbours who never agreed to anything. Capture devices — cameras with computer vision, turnstiles, wearables, drones, 360 walkers — are impersonal only until the induction record joins a card, a face or a tag to a named person and their employer. That join is what makes the whole estate downstream a personal-data processing operation.
- In the project systems lane, footage, access logs and progress imagery land on a platform that several companies can see, models raise alerts on it, and supervisors act. The decisive question here is not technical: it is who decided that this processing should happen and for what purpose. On a joint venture or a deep subcontract chain that decision is often collective and unwritten, which is exactly the condition Article 26 describes — and the subcontractor's own drone or camera adds data the project never specified and cannot account for.
- At handover, the project ends and its archives do not. Recorders, cloud buckets and the supplier's platform hold years of imagery and access records; the information model going to the client carries site photography with identifiable people in it. Every item needs one of three answers — deleted, anonymised or transferred with a stated basis — and the only cheap moment to decide is contract award, because on the last day of a project nobody has budget, time or the supplier's attention.
Step-by-step insights
- The induction join — where site telemetry becomes personal data
- Project teams often argue that the camera watches 'the works, not people', or that the turnstile counts 'passes, not persons'. The argument fails because identifiability includes reasonably available means, and on a site those means are sitting in the induction system: every operative is registered against a name, an employer, a competence card and usually a photograph before they are allowed through the gate. One lookup joins the tag to the person. The design leverage lives exactly here — hold the induction identity in a separate, access-logged store, resolve identity only on a logged request, and most of the estate can run on tokens that mean nothing on their own.
- Computer vision changes the nature of a camera that was already there
- The most common governance mistake on sites is treating an analytics upgrade as an IT change. A camera recording to a loop for security is one processing operation; the same camera running PPE detection and exclusion-zone alerting is a different one — it evaluates every person in frame, continuously, and produces structured records of individual behaviour that can be searched, counted and compared. The EDPB's video guidelines make clear that video processing engages the regulation directly, and the practical consequence is simple: an analytics module switched on by a firmware update is a new purpose, and it needs its own assessment before it is energised.
- The subcontractor's kit — capture you did not specify and cannot account for
- A survey subcontractor flies a drone every Friday. A fit-out subcontractor runs a 360 walk for its own progress claims. A plant supplier's telematics identifies the operator to enforce licences. None of this appears in the principal contractor's register, and all of it happens inside a site the principal contractor controls, on people it inducted. The fix is procurement, not policy: capture activity is registered before it starts, terms cover retention and reuse, and the subcontract says plainly whether imagery may leave the project or train a supplier's models.
- One system, six companies — the joint-controller moment
- The shared site platform is where the controllership question becomes concrete. If the JV board specified the exclusion-zone model, the partners decided the purpose together and Article 26 applies whether or not the deed mentions it. If the principal contractor decided alone and merely gives subcontractors a login, it is the controller and they are recipients. If a subcontractor pulls footage into its own safety programme, it has become a controller for that purpose. Writing the allocation down does not create the obligation — it is the only thing that makes it manageable, because it fixes who answers the worker, the client and the regulator.
- Purpose creep travels along the alert log
- The exclusion-zone alert exists for safety, and everyone agrees. Then the commercial team asks for footage to defend a delay claim, the quality team wants to check who poured the slab, and a supervisor uses last Tuesday's clip in a performance conversation. Each request is reasonable in isolation and each one processes the data for a purpose the assessment and the notice never described. Keep a request log with the reason, the requester and the approval; it is the cheapest control on this page, and it is also the record that tells you when the estate has quietly become something else.
- Practical completion is a data event, not just a commercial one
- On the day the works are handed over, the organisation that made every one of these decisions dissolves. The project team demobilises, the site systems come down, the supplier's platform reverts to its own retention defaults, and the client receives an information model whose contents nobody has examined for personal data. Statutory duties continue — the health and safety file, and for higher-risk buildings the golden thread, both of which the client must be given — but four years of camera footage belongs to none of them. Decide the destination of each class at contract award, price the close-out, and demand a deletion certificate for whatever does not travel.
The five stages of project data governance, in detail
For each stage: what it looks like on a live site, the diagnostic signals a reviewer can check in an afternoon, the anti-pattern that traps project teams there, and what leaving costs.
The five stages are Unmapped, Inventoried, Controlled, Evidenced and Trusted, and they measure how far a project has travelled from creating personal data to being able to account for it — from a site that cannot list its cameras to one that hands over a priced, certified data position at completion. Each stage below is written for a project team rather than a buyer. The hallmarks describe conditions observable on a live site, the diagnostic signals are checks a reviewer can run this week with a site plan and a login, and the anti-pattern is the specific mistake most often made trying to leave that stage. The ladder is ordered by dependency, not by virtue: register before basis, basis before minimisation, controls before allocation, allocation before handover.
Select a stage
Every stage's full detail is in the page source — the selector only changes which panel is visible, so nothing here depends on JavaScript to exist.
Stage 1
Unmapped
27% of operators sit here
The site creates personal data continuously and nobody can name the systems, the purposes or the companies that hold it.
Unmapped is not carelessness. Most contractors at this stage have a privacy notice, a data protection lead at head office and a corporate register that covers HR, payroll and the CRM. What is missing is the project: the live site is a separate data-creating organisation with its own systems, its own suppliers and its own population of people, and nobody has walked it. The obligations exist; the map that would let anyone discharge them does not.
The tell is procurement. Site security cameras are bought against a security budget by a project team under programme pressure, often as part of a hoarding and fencing package. Biometric turnstiles arrive with the access-control contract. Wearables come as a bundle with the plant hire. A subcontractor turns up with a drone and a 360 camera because the survey scope asked for weekly progress capture. Every one of these is a processing decision made by someone with no data-protection remit, on terms nobody read, and the analytics features are increasingly enabled by default.
This stage is uncomfortable to leave because the first honest walk-round always finds something: a camera pointing over the hoarding into a neighbour's garden, a people-analytics feature switched on by a firmware update, three years of footage on an NVR in a cabin that was supposed to be a 30-day loop. Leaders sometimes prefer not to look. That instinct is backwards — regulators reserve their sharpest findings for the organisation that could not answer, and the first question is always the inventory.
In practice
The camera estate nobody could list
A client's data protection officer asks a principal contractor a simple question about a large city-centre project: how many cameras are on the site, what do they see, and how long is the footage kept? The answer takes three weeks to assemble and arrives as a spreadsheet with forty-one entries — including nine cameras the security subcontractor installed and invoiced separately, two with people-counting analytics enabled by the supplier as a product update, and one covering the smoking shelter, which nobody could justify when asked.
What it looks like
- No single list exists of the cameras, readers, tags and drones operating on the project
- The camera contract was signed on site as a security purchase, not as a processing decision
- Subcontractors bring their own capture kit and nobody has seen the terms
- A worker's access request would be answered by phoning round the supply chain
Diagnostic signals you can check this week
- Ask the project team for the site's camera and sensor list; at stage 1 it is compiled on request, not maintained
- Walk the hoarding line and check what each camera actually frames — footpath, neighbouring windows, the welfare unit
- Ask which subcontractors are capturing imagery on site and under whose terms; if the answer is 'the survey team', you are here
- Ask what a worker would receive if they made an access request for their own site data, and how long it would take
Anti-pattern · Asking the supplier whether it is GDPR compliant
The instinctive first move is to email the camera or turnstile vendor and ask for confirmation that the product is GDPR compliant. The answer always comes back yes, and it is close to meaningless: the supplier is describing its own processing, while the decisions the regulation actually tests — why this system, watching whom, at what resolution, kept how long, seen by which of the six companies on site — are yours. A compliant product deployed for an unassessed purpose is an unlawful processing operation with good paperwork attached.
What holds you here
Nobody can name the systems, purposes and companies that touch personal data on the project, so every obligation is unanswerable rather than unmet.
Highest-leverage next move
Walk one live site and build the register: every capture device, what it sees, who bought it, who can watch it, and how long the footage survives.
Cost of leaving
- Effort
- 4–8 weeks
- Team
- Project data lead plus the site manager, with the privacy lead part-time
- Risk
- Low — the work is a walk-round and a register; nothing on site changes yet
- To next stage
- 2–4 months
If this is you, the next step is
A 2–3 week exercise: every camera, reader, tag and capture device on one project, with purposes, holders and retention recorded.
Stage 2
Inventoried
38% of operators sit here
A register exists and the paperwork looks finished, but it describes the company rather than the project — and nothing on site enforces what it claims.
Inventoried is the most common stage on projects and the most deceptive, because the artefacts exist. There is a register with a CCTV row, a DPIA template signed by someone senior, a privacy notice in the induction pack and a line in the subcontract about compliance with data protection law. What is missing is the connection to this project: a company-level entry cannot describe a system that was configured on this site, by this security supplier, watching this population, with an analytics module added in month eight.
The structural problem is that governance and delivery never meet on a project. The register was written at head office from interviews; the site was set up by a team whose success is measured in programme and cost, buying from a supply chain that configures the kit. So the register says thirty days while the recorder keeps everything, and it says 'security purposes' while a supervisor is using last Tuesday's footage in a performance conversation. Neither party is lying — there is simply no mechanism that makes the paper true on the ground.
Time at this stage accumulates risk in a way that is specific to projects: it compounds into handover. Every month of unassessed collection deepens an archive that nobody has agreed how to close, and each new subcontractor inherits an environment where capture is normal and terms are absent. Contractors usually leave stage 2 under external pressure — a union challenge, a client's data protection officer, a neighbour's complaint about a camera. Leaving it deliberately, on the first project rather than the fifth, is considerably cheaper.
In practice
The DPIA that described a different site
A national contractor's assessment for 'site CCTV' was written in 2019, approved once and attached to every project since. On a hospital extension, the same document is on file — but the site now runs computer-vision PPE detection and exclusion-zone alerting added by the supplier as a software update, a biometric turnstile the access-control package specified, and a weekly drone flight by a survey subcontractor. The DPIA describes none of them. It is not a bad document; it is a document about a different site, and the first person to notice is the client's auditor.
What it looks like
- The corporate register mentions 'site CCTV' generically, with no entry for computer-vision analytics
- One company-wide DPIA is reused for every project, including sites it never described
- The privacy notice sits in the induction pack; workers learned about PPE detection from the toolbox talk
- Retention is stated as 30 days while the recorder overwrites only when the disk fills
Diagnostic signals you can check this week
- Ask for the DPIA covering the site you are standing on, then check whether it names the analytics features actually running
- Compare the retention period in the register with the oldest recording still on the recorder
- Ask three operatives from three different employers what the cameras are used for, and compare the answers with the notice
- Check whether the JV agreement or the subcontract says anything about who decides purposes for shared site systems
Anti-pattern · One corporate DPIA for every site
The efficient-looking move is to write the assessment once and reuse it across the portfolio. It fails for a reason peculiar to projects: no two sites have the same population, neighbours, layout or supplier configuration, and it is precisely those variables that the assessment is meant to weigh. A template is genuinely useful — the standing risks, the standard mitigations, the model wording — but the site-specific pages are the assessment. Reusing them is how a contractor ends up holding a well-written document about a project that does not exist.
What holds you here
The register and DPIA describe the company, not this project, and nothing in the site systems enforces what they claim.
Highest-leverage next move
Take the highest-risk system on one live project — usually the camera estate with analytics — and make the paperwork true in the equipment: purpose, configuration, retention, access.
Cost of leaving
- Effort
- 3–6 months
- Team
- Privacy lead, project data lead and the site systems supplier, with the project director sponsoring
- Risk
- Medium — enforcing retention and reconfiguring analytics touches live site systems for the first time
- To next stage
- 3–6 months
If this is you, the next step is
We take one live site and make the register describe reality — retention set in the system, analytics configured to the purpose, notices workers can understand.
Stage 3
Controlled
22% of operators sit here
Controls are enforced in the site systems themselves: assessments precede energisation, models run on the narrowest useful data, and retention is set where the footage lives.
Controlled is the stage where governance moves off the shared drive and into the equipment. Retention becomes a setting on the recorder that someone verified, not a sentence in a policy. Minimisation becomes a camera angle, a masked region over the neighbouring balconies, a model that emits 'zone breach, gate 3' rather than a named person. The assessment becomes a gate in site set-up, sitting alongside the temporary works check and the utilities search — the two disciplines a construction team already respects because neither can be skipped.
The character of the work changes accordingly. Stage 2 problems are documentary; stage 3 problems are engineering and procurement: how to run PPE detection at the edge so identifiable frames never leave the site, how to give the safety team the ten seconds around an alert without giving the commercial team a searchable archive, how to configure a turnstile so that the card path and the biometric path are equally easy. None of this is exotic. All of it has to be specified before the package is let, which is why stage 3 is really a procurement capability.
The constraint that emerges is proof across the chain. The controls are real, but the evidence is scattered between a site file, a supplier's portal and someone's inbox — and the chain question is still open. The JV agreement is silent, the subcontracts say 'comply with data protection law' and nothing else, and no one has written down who decided that the exclusion-zone model should exist. The project is compliant in substance and cannot demonstrate it quickly, which in front of a client's auditor or a union representative is uncomfortably close to not being compliant at all.
In practice
The exclusion-zone alert that never named anyone
On a rail possession, a contractor runs computer vision on the existing camera estate to detect people entering the exclusion zone around a plant movement. The model emits an event with the zone, the time and a low-resolution crop; the supervisor's phone shows the zone, not a face. Identity is only resolved if the event becomes an incident, through a documented request that two named people can make and that is logged. The safety benefit is unchanged. The intrusion — and the paperwork it would otherwise require — is a fraction of what a face-searchable archive would have created.
What it looks like
- No camera or reader is energised on site until its assessment is signed and its retention is configured
- Vision models raise zone and PPE events without publishing identity by default
- Biometric access has a genuine, offered alternative and workers know it exists
- Drone and 360 capture runs to a published flight plan with notice to workers and neighbours
Diagnostic signals you can check this week
- Ask to see the retention setting on the recorder, then check the timestamp of the oldest file actually stored
- Ask the supervisor how they receive an alert; if the default view names a person, minimisation has not been designed
- Ask a new starter to show you the non-biometric route through the turnstile and time it
- Ask an engineer to point at the control behind any mitigation in the DPIA — at stage 3 they can, on site
Anti-pattern · Letting the safety camera become the productivity camera
Once the estate exists, the requests start: use the exclusion-zone footage to settle a delay claim, run the PPE model over last month to rank subcontractors, check who was on the deck at 14:00 for a disciplinary. Each is individually reasonable and collectively fatal, because the lawful basis, the assessment and the notice all described safety. Purpose creep is the single most common way a well-built stage-3 site drops back to stage 2 — and it is documented in the request log, which is exactly where a regulator or a union will look first.
What holds you here
Controls are real but the chain is undocumented — nobody has written down who decides purposes across the JV and the subcontract chain, or how to prove any of it quickly.
Highest-leverage next move
Write the controller allocation down: an Article 26 arrangement for the shared systems, flow-down terms in the subcontracts, and one project evidence pack that a client auditor can read.
Cost of leaving
- Effort
- 4–8 months
- Team
- Privacy lead, project data lead, site systems supplier, and the commercial manager who lets the packages
- Risk
- Medium — the evidence work touches every subcontract and the JV agreement
- To next stage
- 4–8 months
If this is you, the next step is
We build the project evidence pack from the controls you already run: DPIA register, purpose log, retention proof, chain allocation.
Stage 4
Evidenced
9% of operators sit here
The project can prove it: a live register, assessments tied to site changes, a written joint-controller arrangement, consultation records and an agreed handover data schedule.
Evidenced is the stage most contractors believe they have reached and few actually have. The distinguishing property is speed of proof on the project, not at head office. A client's auditor asks who can watch the gate camera and gets a role list the same afternoon. A union representative asks what changed when the PPE model was updated and gets the assessment delta. A worker asks what the site holds about them and gets an answer inside the statutory month, including the access logs held by the turnstile supplier, because somebody mapped that relationship when the package was let.
The economics invert here, and on projects the effect is unusually direct. Below this stage every external question is a fire drill that pulls the project team off the programme. At stage 4 the marginal cost of answering approaches zero, and the evidence starts winning work: public-sector and regulated clients increasingly score data-handling posture in prequalification, framework renewals ask for it, and a contractor that can hand over an information model with a clean personal-data position is a contractor whose client's own compliance team stops treating handover as a risk.
What still limits stage 4 is that the discipline lives with the project team rather than in the operating model. The next bid team writes it from scratch, the next JV negotiates the arrangement from first principles, and the subcontract flow-down depends on which commercial manager drafts the package. Meanwhile the EU AI Act's obligations for AI used to monitor and evaluate workers arrive on top of the GDPR work, and a project-by-project posture meets them project by project. The move to stage 5 is making governance part of how the business wins and closes work, not part of how one team runs one site.
In practice
The client audit answered from the site office
Six months into a two-year infrastructure package, the client's information governance team runs an audit on the JV. They ask for the camera register, the assessment for the plant-proximity system, the list of people who can retrieve footage, and the retention configuration. The JV's project data lead answers all four from the site office within a day, and produces the joint-controller arrangement from the JV deed when asked who decided the purposes. The audit closes with two observations and no actions. The same client's previous audit of the same contractor, three years earlier, ran for eleven weeks.
What it looks like
- A project-level register that names every system, purpose, holder and retention period
- An Article 26 arrangement in the JV deed, with a single published contact point for data subjects
- Assessment review triggered by site change — new package, new supplier, new analytics module
- The handover data schedule was agreed at contract award, not discovered at practical completion
Diagnostic signals you can check this week
- Ask for the project register and check its last-updated date against the last package let on site
- Ask who the published contact point is for a worker's data question, and whether subcontractors' operatives know it
- Run a dry access request covering the turnstile supplier's records as well as your own systems
- Ask when the handover data schedule was agreed; 'at award' is stage 4, 'we will sort it at PC' is not
Anti-pattern · Evidence that lives at head office
The registers are immaculate, the assessments are filed, the policies are versioned — and all of it sits on the corporate intranet, two organisational layers away from the site that generates the data. When the question arrives it arrives on the project: a neighbour at the gate, a union representative in the canteen, a client's auditor in the site office. If the answer requires an email to head office and a two-day wait, the project is running stage-3 evidence with stage-4 filing. Put the pack where the site is, and make the project team its owner.
What holds you here
Governance is provable on this project but not built into how work is won, let and closed — and AI Act obligations for worker-monitoring systems are arriving on top.
Highest-leverage next move
Push the artefacts upstream and downstream: prequalification questions, standard JV arrangement, subcontract flow-down clauses, and a priced handover data schedule in every contract.
Cost of leaving
- Effort
- 6–12 months
- Team
- Privacy lead embedded with the project, commercial lead for flow-down, JV partner counterparts, union or works-council liaison
- Risk
- Medium — the work is operating rhythm and contract drafting more than build, and rhythms are harder to ship
- To next stage
- 6–12 months
If this is you, the next step is
We turn one project's evidence pack into the standard set your next bid, JV and site set-up inherit automatically.
Stage 5
Trusted
4% of operators sit here
Governance travels with the work: it is asked for at prequalification, flowed down in subcontracts, and closed out at handover as a priced, certified deliverable.
Trusted is narrower and more operational than the word suggests. It does not mean a contractor is admired; it means the governance system is credible enough that the parties around the project extend it the benefit of the doubt, and the project team stops routing around it. Clients accept the handover pack instead of commissioning their own review. Union representatives start from 'show us what changed' rather than from opposition. Site managers reach for the standard camera specification because it is the paved road, not because someone will check. The system has become cheaper to follow than to bypass, which is the only condition under which governance survives a programme squeeze.
The EU AI Act is the proving ground for this stage. AI used for monitoring and evaluating workers sits in the regulation's high-risk category, which brings risk management, logging, data-quality, transparency and human-oversight obligations for deployers on a statutory timetable, and the workplace prohibitions — notably inferring emotions at work — apply regardless of risk class. A trusted contractor meets most of this from the evidence it already generates: the DPIA extends to a fundamental-rights view, the alert logs exist, the oversight roles are named in the safety management system. Contractors below stage 4 will experience the same deadlines as a second, parallel compliance programme running against the same programme dates.
Sustaining stage 5 is a change-management discipline and this is where regression starts. Every project is a new organisation with a new population, a new supply chain and a new client. A framework renewal brings a supplier whose analytics defaults differ. An acquisition brings sites nobody has walked. A new client demands person-level dashboards the current design deliberately cannot produce. Each is small; each invalidates an assessment somewhere. The stage-5 contractor ties governance review to project events — site set-up, package award, supplier change, model update, handover — rather than to the calendar, and treats a governance regression with the seriousness of a safety observation.
In practice
The handover that included a deletion certificate
At practical completion on a data-centre project, the contractor hands over the information model, the health and safety file and a two-page data schedule: what personal data travels to the client and why, what stays with the contractor under statutory retention, and what has been destroyed — with a certificate from the systems supplier covering the camera archive and the biometric templates, dated the week after the final snagging visit. The client's compliance team signs it off in a day, and asks whether the same schedule can be added to the framework's standard particulars.
What it looks like
- Data-handling posture is cited in won bids and framework renewals, not only in audits
- Every subcontract carries flow-down terms on capture, retention and deletion that suppliers actually price
- Union and works-council engagement on new site monitoring is measured in weeks and recorded
- Handover includes a data schedule, a transfer list and deletion certificates for what does not travel
Diagnostic signals you can check this week
- Look for data-handling posture cited in bid documents and framework returns, not just audit responses
- Time the last consultation on a new monitoring system with union or works-council representatives
- Check whether the last three subcontract packages carried priced flow-down terms on capture and deletion
- Ask to see the most recent handover data schedule and the deletion certificates behind it
Anti-pattern · Treating handover as the end
The certificate is signed, the project team demobilises, and everyone assumes the personal-data question closed with it. It did not: the client now holds an information model that may contain identifiable site imagery, the systems supplier may still hold an archive under its own retention default, and the contractor keeps statutory records for years. Each of those is a live processing operation with a controller, and the day the project team disbanded is the day nobody owned any of them. Close the loop deliberately — named owner, stated period, evidence — or the archive outlives everyone who understood it.
What holds you here
Sustaining trust is change management across a portfolio of temporary organisations: every new project, supplier, model update and client can silently invalidate an assessment.
Highest-leverage next move
Wire governance review to project events — site set-up, package award, supplier change, model update, handover — and rehearse the awkward scenarios before they arrive unannounced.
Cost of leaving
- Effort
- Continuous
- Team
- Privacy lead inside the delivery business, bid and commercial teams, standing supplier assurance, workforce representatives
- Risk
- Concentrated — low frequency, high consequence; the cost of failure is client trust and workforce consent, neither of which rebuilds on a programme timescale
If this is you, the next step is
We run a scenario — worker access request, union challenge, client audit, AI Act query — against one live site and report where it creaks.
Where construction and infrastructure projects actually sit
The distribution across the ladder, why Inventoried is the plateau on projects specifically, and the two dimensions that drag the average down.
Most projects sit at Inventoried: the corporate paperwork exists and the site runs ahead of it. That gap is structural rather than cultural. Governance artefacts are written by a permanent organisation at head office, while the data is created by a temporary organisation on site that was assembled six months ago, buys its own kit under programme pressure, and will be dissolved before anyone reviews the register. The distribution below is illustrative — it synthesises regulator guidance on workplace monitoring rather than reporting a measured survey — but the shape is the one every auditor recognises.
Where projects sit on the data-governance ladder
Illustrative distribution across the five stages, synthesised from ICO employment-monitoring and video-surveillance guidance — not a measured survey. Inventoried is the plateau: the register exists, and nothing on site enforces it. The share that can prove its position quickly is small, which is why evidence has become a prequalification asset rather than an audit chore.
Share of projects (illustrative)
- 27% — 1 · Unmapped
- 38% — 2 · Inventoried (the plateau)
- 22% — 3 · Controlled
- 9% — 4 · Evidenced
- 4% — 5 · Trusted
Source: Illustrative, synthesised from ICO guidance on monitoring workers
Two of the four dimensions do most of the damage. Controller roles across the chain is the lowest-scoring dimension on almost every joint venture, because the question is genuinely hard and nobody owns it: the JV deed is drafted by commercial lawyers around risk and profit share, the site systems are specified by a delivery team, and the moment where those two conversations should have met never appears in anyone's programme. Retention and handover is the second, and it fails for a simpler reason — the person who would have to act is demobilised by the time the question becomes urgent.
The dimensions are not independent. A project that scores well on inventory and badly on chain roles is holding a precise description of processing it cannot allocate; a project with strong controls and no handover schedule is running a clean site that will leave an unowned archive behind it. The assessment scores all four separately for that reason, and in practice the lowest one sets the stage — the same way the weakest temporary works detail sets the load a structure can actually carry.
Where personal data is created on a site
Eight site systems most project teams treat as operational kit, the personal data inside each, whose data it actually is, and the basis that survives scrutiny.
Personal data is created on a site wherever a device can be joined to a person, and on a construction project almost everything can. The join is one hop away and it is always the same hop: the induction record, which ties a card, a face or a tag to a named individual and an employer before that individual is allowed past the gate. GDPR does not care that the camera was bought to deter theft or that the tag was bought to keep people away from a slew radius. If a person is identifiable from the data plus reasonably available means, the system is processing personal data and needs a purpose, a basis, a retention limit and a place in the register. The table below maps the eight systems that carry most of the risk on a modern site.
| Site system | Personal data inside it | Whose data it is | Basis that usually survives | The project watch-out |
|---|---|---|---|---|
| Site CCTV with computer vision | Continuous imagery of everyone in frame, plus structured events: PPE state, zone entry, plant proximity, time and location | Every worker on site whoever employs them, visitors, and passers-by at the boundary | Legitimate interests with a documented LIA, safety stated as the specific interest | An analytics module switched on by a supplier update is a new purpose; boundary cameras routinely see the public footpath |
| Biometric turnstiles and access control | Facial or fingerprint templates processed to identify a specific individual | Operatives of every employer on site, including agency and short-duration labour | An Article 9 condition on top of an Article 6 basis — which is why most projects should use cards or fobs | 'The client asked for it' is not necessity; the non-biometric route must be real, offered and equally quick |
| Access cards, inductions and competence records | Name, employer, competence card, photograph, right-to-work evidence, in and out times | Every inducted person, held by the principal contractor for the whole chain | Legal obligation for statutory duties; legitimate interests or contract for the rest | Attendance records drift into productivity and disciplinary use; some jurisdictions compel presence registration |
| Wearables and proximity tags | Position within the site, proximity and near-miss events, sometimes physiological or fatigue signals | Operatives wearing them — frequently employed by a subcontractor, not by the tag's buyer | Legitimate interests with an LIA; an Article 9 condition if health signals are processed | Continuous individual location is far more intrusive than a zone breach; welfare and rest areas must be excluded at source |
| Drone and 360-camera capture | Imagery of workers, plant, neighbouring properties, gardens, windows, vehicles and people beyond the boundary | Workers, neighbours and the public, none of whom were inducted | Legitimate interests for progress and survey purposes; aviation rules apply separately and do not substitute | Incidental capture past the red line, and progress imagery published to social media without a second look |
| Site photographs and defect records in the CDE | Faces, number plates, tattoos and workers identifiable by task, embedded in quality and progress records | Workers and subcontractors, indexed against packages and dates | Legitimate interests for the record; contract where the imagery is a deliverable | This is the class most likely to be handed to the client and kept for the life of the asset |
| Plant telematics and operator identification | Machine utilisation and event data linked to an operator through a key card or licence check | Operators, usually employed by a plant supplier rather than the contractor | Legal obligation for competence checks; legitimate interests for utilisation and maintenance | The plant supplier is a controller in its own right, so the operator has two organisations watching one seat |
| Model training corpora built from site imagery | Everything above, frozen at the moment of capture and retained to retrain models | Everyone the site ever captured, including people who left years earlier | Compatibility with the original purpose under Article 6(4), or a fresh basis of its own | 'We already have the footage' is not a basis, and corpora outlive both the project and the conversation that justified them |
Personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
Purpose limitation is the principle that does the heavy lifting on a site, because site systems are unusually easy to repurpose. The estate is already installed, the footage is already retained, and every new question — who was on the deck, which gang was slow, who left the gate open — can be answered from data collected for safety or security. The EDPB's guidelines on video devices (opens in a new tab), the ICO's video surveillance guidance (opens in a new tab) and the Article 29 Working Party's Opinion 2/2017 on data processing at work (opens in a new tab) all approach workplace monitoring the same way: the question is never whether monitoring is allowed in principle, but whether this specific processing, at this granularity, for this purpose, is proportionate to what it achieves — and whether the people in the data were told.
The special-category corners a site walks into without noticing
Biometric identification at the turnstile, health and fitness-to-work data from occupational health or fatigue wearables, and drug and alcohol testing all sit under Article 9 (opens in a new tab), which requires a separate condition on top of the ordinary basis — the ICO's biometric recognition guidance (opens in a new tab) sets out how narrow those conditions are in practice. So does anything that reveals trade-union membership — and monitoring that records who attended a consultation meeting, or which operatives a union representative spoke to, does exactly that. Given the industry's own history, this is the corner to be most careful in.
Neighbours and the public are data subjects too
A boundary camera that sees the footpath, a drone that overflies gardens, a 360 walk that captures a neighbouring office through a window: none of these people were inducted, none received a notice at the gate, and all of them are identifiable. Aim and mask at installation, plan flight lines to the red line, and treat imagery beyond the boundary as a defect to be fixed rather than a by-product to be filed. Flight rules from the UK Civil Aviation Authority (opens in a new tab) and EASA (opens in a new tab) govern the flying; they say nothing about the recording, and complying with one is routinely mistaken for complying with the other.
Agency and short-duration labour is where transparency fails
An operative on site for three days through an agency receives the induction, signs for the PPE and passes through the turnstile like everyone else — and is the least likely person on site to have read anything about the monitoring. Transparency has to work at the gate, in the languages actually spoken on the project, in a form someone can absorb in the two minutes they will give it. A privacy notice that only exists inside a 60-page induction pack is a notice for the auditor, not for the worker.
Statutory presence registration is a live example of a legal obligation basis
In Belgium, contractors on construction works above a statutory value threshold must make a declaration of works and register the daily presence of everyone performing the work, through the federal checkinatwork formalities (opens in a new tab). Where a rule like this applies, the basis for collecting who was on site and when is settled by law — and the interesting governance question becomes what else the project does with the same records once it holds them.
One principle organises the whole map: a site event is personal data whenever it can be traced to one human, and genuinely anonymous the moment it cannot. That boundary is an engineering artefact — where the induction join sits, who can perform it, whether the model emits a zone or a face, what the aggregate suppresses — which is why data governance on a project is a design and procurement discipline first, and a documentation discipline second. Everything the register records was decided when a package was let.
When a site system needs a DPIA, and where the AI Act lands
Site monitoring meets the Article 35 triggers several times over — and the same systems are the ones the EU AI Act treats as high-risk worker management.
A DPIA is required before a site monitoring system goes live whenever the processing is likely to be high risk, and computer-vision site monitoring clears that bar several times over: it is systematic monitoring of individuals, it happens in a workplace where the people in the data are in a dependent position, it uses innovative technology, and on a large project it operates at scale. Article 35 (opens in a new tab) sets the duty and the ICO's DPIA guidance (opens in a new tab) operationalises it as a screening list — as a working rule, two or more triggers means run the assessment. The trap on projects is timing rather than judgement: the assessment has to be finished before the system is energised, and site set-up moves faster than any governance process that is not part of it.
None of this is an argument against monitoring. Construction remains one of the most dangerous sectors to work in, and the Health and Safety Executive's construction pages (opens in a new tab) set out why exclusion zones, plant separation and PPE discipline are enforced the way they are: the hazards that computer vision is pointed at are the ones that kill people. A DPIA is not a hurdle placed in front of that. It is the document in which a contractor writes down that the safety purpose is real, that the design collects the least it can while still achieving it, and that somebody accountable weighed the intrusion — which is exactly the argument a project will want on file the first time a union representative, a client or a regulator asks why the cameras are there.
DPIA trigger check for a site system
Tick every condition that applies to the system you have in mind — the CV camera estate, the turnstile, the proximity tags, the weekly drone flight. Two or more ticks means run the DPIA before energisation; the note below tells you what your tally usually implies on a project. Works without JavaScript.
0 of 6 ticked
0 ticked — check you assessed the right system
Almost nothing on a modern site scores zero: a camera estate with any analytics, a turnstile, or a proximity tag will trip at least one condition. If your honest count really is zero — say, a fixed progress camera on a time-lapse with no people visible at that resolution — record the screening anyway. The note that you assessed and found no high risk is itself the accountability artefact a regulator expects to see.
1 of 6 — below the threshold, and rarely stable
One trigger sits under the formal threshold, but on a project one trigger becomes three the moment the supplier ships an analytics update or the client asks for gate reporting. Write the screening down, attach a review trigger to any change of scope or software, and move on. That review trigger is the cheapest thing on this page.
2 of 6 — the threshold: run the DPIA before energisation
Two triggers is the regulators' working threshold, and on a site the practical consequence is a sequencing one: the assessment belongs in the site set-up programme alongside the temporary works check, not in a governance queue at head office. Scoped to one system, a first site DPIA is typically two to three weeks, most of it the data-flow mapping the project needs anyway.
3 of 6 — the standard camera-estate profile
Three triggers describes a typical CV camera estate on a live project. The assessment is mandatory and its hardest section is necessity: why this coverage, this resolution, this retention, this alert design. The minimisation levers on this page — masking, edge processing, events without identity, the separate induction join — are the raw material for that section, and they are also what makes the answer come out in your favour.
4 of 6 — biometrics or combined datasets are in scope
Four triggers usually means biometric entry or a system joined to induction and HR records. Two things follow: you need an Article 9 condition as well as an ordinary lawful basis, and you need a genuine alternative route through the gate that is offered rather than mentioned. Involve worker representatives at this point — their input is evidence, and it is far cheaper before go-live than after.
5 of 6 — high risk on both regimes; build the evidence once
At five triggers the system is squarely inside the AI Act's worker-management category as well as GDPR's high-risk processing. Build the artefacts once: one risk assessment with a fundamental-rights lens, one logging design, one human-oversight specification naming the site roles that hold it, referenced from both compliance files. Two parallel programmes for one camera estate is how projects lose a quarter.
6 of 6 — the full profile, including people who never agreed
All six ticked describes continuous, evaluative, biometric-linked monitoring of a dependent workforce, combined with other records and spilling past the hoarding. It is not undeployable — plenty of major projects run exactly this lawfully — but it needs the whole discipline: DPIA with recorded worker consultation, aggressive minimisation at the camera, an offered alternative to biometrics, boundary masking, and a residual-risk sign-off somebody senior is willing to own in writing.
The EU AI Act arrives on top of GDPR rather than instead of it, and it lands on precisely the systems this page is about. The AI Act (opens in a new tab) classifies AI intended to monitor and evaluate the performance and behaviour of people at work as high-risk, which captures PPE and behaviour analytics, productivity inference from access and plant data, and any allocation model that decides who works where. It also prohibits outright the use of AI to infer emotions in the workplace, which rules out the fatigue-and-mood inference some site camera products advertise. Deployer duties are the ones a contractor feels: competent human oversight, input data that is relevant for the purpose, retention of the system's logs, and — the duty most likely to catch a project unaware — informing workers' representatives and affected workers before a high-risk system is put into service at the workplace. The European Commission's AI Act pages (opens in a new tab) track the phased application dates.
Worker consultation is the other duty that arrives from several directions at once, and on a project it is also the cheapest evidence available. Article 88 (opens in a new tab) lets member states set their own rules for processing in the employment context, including through collective agreements, so the applicable standard on a site in Berlin is not the standard on a site in Birmingham. EU law on informing and consulting employees (opens in a new tab) applies on top, and in Germany the Works Constitution Act (opens in a new tab) gives works councils co-determination rights over technical devices capable of monitoring workers — which in practice means agreement before installation, not notification afterwards. On a multinational JV these regimes stack, and the population on site may include posted workers whose home-state representatives also have standing. Consult early, record what changed as a result, and attach the record to the assessment: a balancing test with the workforce's fingerprints on it survives challenge, and one written alone in a legal team rarely does.
| Site system | DPIA position | AI Act position | What the deployer has to do on site |
|---|---|---|---|
| CV cameras: PPE and exclusion-zone alerting | Required — systematic monitoring of workers at scale | High-risk worker monitoring where output evaluates behaviour | Named oversight role, alert log retained, workers and their representatives informed before go-live |
| Biometric turnstile | Required — biometric identification plus dependent data subjects | Biometric categorisation and remote identification are tightly restricted; workplace deployment needs care | Article 9 condition, an offered non-biometric route, template retention limited to the site duration |
| Wearables and proximity tags | Required where individuals are identifiable and tracked continuously | High-risk if the output is used to evaluate the person rather than to warn them | Zone-level rather than person-level output by default, welfare areas excluded, health signals separately justified |
| Drone and 360 progress capture | Usually required — large-scale imagery including people who were never informed | Not automatically high-risk; becomes so if the imagery drives worker evaluation | Published flight plan and notice, boundary masking, review before any external publication |
| Allocation or scheduling models using worker data | Required — evaluation with effects on individuals | Squarely inside the employment and workers-management category | Human decision documented, Article 22 analysis, contestation route the workforce actually knows about |
| Progress and quality imagery in the CDE | Screening record at minimum; required if faces are searchable | Not high-risk in itself; training a behaviour model on it changes that | Redaction rules before handover, and terms saying whether a supplier may train on the imagery |
The EDPB's Opinion 28/2024 on AI models (opens in a new tab) closes the loop on the corpus question that site DPIAs now have to answer. Personal data inside a training pipeline remains personal data; a claim that a trained model is anonymous is something to demonstrate rather than assume; and a model trained on unlawfully collected material is not cleansed by the training process. For a contractor whose supplier proposes to improve its PPE detector on four years of your site footage, that has a concrete consequence: the reuse needs its own compatibility analysis or its own basis, and the answer belongs in the contract before the first camera is commissioned, not in a renewal negotiation afterwards. The ICO's guidance on AI and data protection (opens in a new tab) sets out the same expectations for UK projects.
What enforcement and precedent look like in construction
Three publicly documented cases about workers' data in and around construction sites, read against the ladder. Each links to the regulator's or the public body's own material.
Regulators have already ruled on the exact data patterns site monitoring is built from — worker records shared across a contractor chain, biometric identification used to control access to work, and statutory registration of who is on site. None of the three cases below punishes monitoring in principle. Each turns on the governance around it: whether anyone could account for the data, whether a less intrusive method was available, and whether the purpose the data was collected for is the purpose it is used for. That distinction is the whole argument of this page, and it is worth reading in the regulators' own words rather than in a summary.
Three cases read against the ladder
Findings and figures as published by the regulators and public bodies themselves. Stage placements are our editorial reading against the project governance ladder, not the regulator's language. The photographs are industry scenes from our image library, not photographs of the organisations named — none of these is an Atomic Loops engagement.
The Consulting AssociationUK construction chain · ICO investigation and prosecution, from 200911
- Challenge
- Worker information moved between construction firms through a third party with no accountability attached to it. As the ICO records, the organisation kept indexes on thousands of construction workers — often union members or workers who had raised health and safety concerns — including names, addresses, press cuttings and character assessments.
- Approach
- Firms checked the names of prospective workers against the database before engaging them, so a record created by one company determined whether a person could work for another. The ICO investigated after raiding the organisation's offices in February 2009.
- Reported outcome
- The ICO forced the organisation to shut down and prosecuted its operator, then made details of the database available to the people on it, which supported later legal action; in 2016 trade unions settled with construction firms in a compensation package the ICO describes as worth millions of pounds.
- What it shows about the curveThis is the Unmapped stage at its most consequential: worker data crossing company boundaries on a project, with no register, no basis and no allocated controller. The systems have changed — the shared database is now a shared site platform — and the structural question has not.
ICO — construction employment deny list (opens in a new tab)
Serco Leisure and associated trustsWorkplace attendance monitoring · ICO enforcement notices, February 202423
- Challenge
- Facial recognition and fingerprint scanning were used to check the attendance of more than 2,000 employees across 38 leisure facilities, and to pay them for their time. Biometric identification of a workforce for attendance is the same pattern as a biometric site turnstile, which is why the decision reads directly across to construction.
- Approach
- The ICO assessed necessity and proportionality rather than banning biometric technology: it found the organisations had failed to show why facial recognition and fingerprint scanning were necessary or proportionate for attendance checking when less intrusive means such as ID cards or fobs were available, and that employees had not been proactively offered an alternative.
- Reported outcome
- Enforcement notices required the organisations to stop all processing of biometric data for attendance monitoring and to destroy the biometric data they are not legally obliged to retain, within three months of the notices being issued.
- What it shows about the curveThe lesson for a site gate is precise: the question is never whether biometrics work, it is whether you can show a card would not. 'Faster throughput at shift change' is an argument that has to be evidenced, and an alternative route has to be genuinely offered, not merely available on request.
ICO — enforcement action, Serco Leisure Operating Limited and associated trusts (opens in a new tab)
Belgian federal presence registrationStatutory site-presence registration · Belgium, FPS Employment34
- Challenge
- Belgium requires contractors performing construction works above a statutory value threshold to make a declaration of works and to register, daily, the presence of the people carrying out the work — including subcontractors and self-employed workers in the chain.
- Approach
- Registration runs through federal services rather than through each contractor's own system, so the purpose, the data set and the recipients are fixed by law instead of being decided package by package on site.
- Reported outcome
- The formalities are published by the Federal Public Service Employment, Labour and Social Dialogue, which sets out the declaration and presence-registration duties that apply to construction works and to posted workers in the chain.
- What it shows about the curveWhere a legal obligation applies, the basis for knowing who was on site is settled and the governance question moves on: what else does the project do with the same records? Attendance data collected under a statutory duty does not carry a licence to run productivity analytics on it — that is a different purpose needing its own basis and its own assessment.
FPS Employment, Labour and Social Dialogue (Belgium) — construction formalities (opens in a new tab)
Read together, the three describe the same fault line from different sides. The first is what happens when worker data crosses company boundaries with nobody accountable for it — the failure mode a construction project reproduces every time six firms share one system with no written allocation. The second is a regulator applying the necessity test to a technology choice and finding the cheaper, duller option adequate. The third is a reminder that some site data collection is compelled, which settles the basis and sharpens the purpose-limitation question rather than removing it. None of the three is about AI, and all three are about the governance an AI system inherits the moment it is pointed at a workforce.